Cross Site Scripting Vulnerability in D-Link DIR-816 by D-Link
CVE-2025-1392
5.1MEDIUM
What is CVE-2025-1392?
A vulnerability exists in the D-Link DIR-816 router, specifically in the functionality accessed through /cgi-bin/webproc?getpage=html/index.html&var:menu=24gwlan&var:page=24G_basic. By manipulating the SSID argument, an attacker can execute cross site scripting attacks remotely. This vulnerability affects devices that are no longer supported by D-Link, allowing potential exploitation due to its public disclosure.
Affected Version(s)
DIR-816 1.01TO